
(2024)ISFS問題集と練習テスト(80問題)
ガイド(2024年最新)リアルなEXIN ISFS試験問題
この認定試験は、情報セキュリティの概念、脅威、リスク管理、セキュリティコントロール、ISO/IEC 27001など、様々なドメインをカバーしています。試験はこれらのドメインに対する理解をテストし、試験に合格することで、市場で優れた情報セキュリティプロフェッショナルとして認められることができます。
ISO/IEC 27001標準は、情報セキュリティ管理のために最も広く認識されている国際標準です。組織が情報資産を管理および保護するためのフレームワークを提供します。 Exin ISFS認定試験は、この基準に基づいて、情報セキュリティ管理の基本的な概念と原則をカバーしています。
質問 # 32
What is the relationship between data and information?
- A. Data is structured information.
- B. Information is the meaning and value assigned to a collection of data.
正解:B
解説:
Explanation
質問 # 33
What is the greatest risk for an organization if no information security policy has been defined?
- A. Too many measures are implemented.
- B. Information security activities are carried out by only a few people.
- C. If everyone works with the same account, it is impossible to find out who worked on what.
- D. It is not possible for an organization to implement information security in a consistent manner.
正解:D
質問 # 34
You work in the office of a large company. You receive a call from a person claiming to be from the Helpdesk.
He asks you for your password. What kind of threat is this?
- A. Social Engineering
- B. Organizational threat
- C. Natural threat
正解:A
質問 # 35
Which is a legislative or regulatory act related to information security that can be imposed upon all organizations?
- A. ISO/IEC 27001:2005
- B. Intellectual Property Rights
- C. ISO/IEC 27002:2005
- D. Personal data protection legislation
正解:D
質問 # 36
What is an example of a security incident?
- A. A file is saved under an incorrect name.
- B. You cannot set the correct fonts in your word processing software.
- C. The lighting in the department no longer works.
- D. A member of staff loses a laptop.
正解:D
質問 # 37
You have just started working at a large organization. You have been asked to sign a code of conduct as well as a contract. What does the organization wish to achieve with this?
- A. A code of conduct prevents a virus outbreak.
- B. A code of conduct helps to prevent the misuse of IT facilities.
- C. A code of conduct gives staff guidance on how to report suspected misuses of IT facilities.
- D. A code of conduct is a legal obligation that organizations have to meet.
正解:B
質問 # 38
A well executed risk analysis provides a great deal of useful information. A risk analysis has four main objectives. What is not one of the four main objectives of a risk analysis?
- A. Establishing a balance between the costs of an incident and the costs of a security measure
- B. Determining relevant vulnerabilities and threats
- C. Determining the costs of threats
- D. Identifying assets and their value
正解:C
質問 # 39
Why is air-conditioning placed in the server room?
- A. It is not pleasant for the maintenance staff to have to work in a server room that is too warm.
- B. When a company wishes to cool its offices, the server room is the best place. This way, no office space needs to be sacrificed for such a large piece of equipment.
- C. In the server room the air has to be cooled and the heat produced by the equipment has to be extracted.
The air in the room is also dehumidified and filtered. - D. Backup tapes are made from thin plastic which cannot withstand high temperatures. Therefore, if it gets too hot in a server room, they may get damaged.
正解:C
質問 # 40
You have an office that designs corporate logos. You have been working on a draft for a large client. Just as you are going to press the <save> button, the screen goes blank. The hard disk is damaged and cannot be repaired. You find an early version of the design in your mail folder and you reproduce the draft for the customer. What is such a measure called?
- A. Corrective measure
- B. Preventive measure
- C. Reductive measure
正解:A
質問 # 41
Logging in to a computer system is an access-granting process consisting of three steps: identification, authentication and authorization. What occurs during the first step of this process: identification?
- A. The first step consists of checking if the user is using the correct certificate.
- B. The first step consists of checking if the user appears on the list of authorized users.
- C. The first step consists of comparing the password with the registered password.
- D. The first step consists of granting access to the information to which the user is authorized.
正解:B
質問 # 42
Which of the following measures is a corrective measure?
- A. Installing a virus scanner in an information system
- B. Restoring a backup of the correct database after a corrupt copy of the database was written over the original
- C. Making a backup of the data that has been created or altered that day
- D. Incorporating an Intrusion Detection System (IDS) in the design of a computer centre
正解:B
質問 # 43
You read in the newspapers that the ex-employee of a large company systematically deleted files out of revenge on his manager. Recovering these files caused great losses in time and money. What is this kind of threat called?
- A. Human threat
- B. Natural threat
- C. Social Engineering
正解:A
質問 # 44
What action is an unintentional human threat?
- A. Incorrect use of fire extinguishing equipment
- B. Theft of a laptop
- C. Social engineering
- D. Arson
正解:A
解説:
Explanation/Reference:
質問 # 45
You work in the IT department of a medium-sized company. Confidential information has got into the wrong hands several times. This has hurt the image of the company. You have been asked to propose organizational security measures for laptops at your company. What is the first step that you should take?
- A. Appoint security personnel
- B. Formulate a policy regarding mobile media (PDAs, laptops, smartphones, USB sticks)
- C. Encrypt the hard drives of laptops and USB sticks
- D. Set up an access control policy
正解:B
解説:
Explanation/Reference:
質問 # 46
Some threats are caused directly by people, others have a natural cause. What is an example of an intentional human threat?
- A. Lightning strike
- B. Flood
- C. Arson
- D. Loss of a USB stick
正解:C
質問 # 47
You are the owner of a growing company, SpeeDelivery, which provides courier services. You decide that it is time to draw up a risk analysis for your information system. This includes an inventory of the threats and risks.
What is the relation between a threat, risk and risk analysis?
- A. A risk analysis identifies threats from the known risks.
- B. A risk analysis is used to remove the risk of a threat.
- C. A risk analysis is used to clarify which threats are relevant and what risks they involve.
- D. Risk analyses help to find a balance between threats and risks.
正解:C
質問 # 48
You are the first to arrive at work in the morning and notice that the CD ROM on which you saved contracts yesterday has disappeared. You were the last to leave yesterday. When should you report this information security incident?
- A. This incident should be reported immediately.
- B. You should first investigate this incident yourself and try to limit the damage.
- C. You should wait a few days before reporting this incident. The CD ROM can still reappear and, in that case, you will have made a fuss for nothing.
正解:A
質問 # 49
Which type of malware builds a network of contaminated computers?
- A. Logic Bomb
- B. Trojan
- C. Virus
- D. Storm Worm or Botnet
正解:D
質問 # 50
Under which condition is an employer permitted to check if Internet and email services in the workplace are being used for private purposes?
- A. The employer is permitted to check this if a firewall is also installed.
- B. The employer is permitted to check this if the employee is informed after each instance of checking.
- C. The employer is permitted to check this if the employees are aware that this could happen.
- D. The employer is in no way permitted to check the use of IT services by employees.
正解:C
質問 # 51
You own a small company in a remote industrial areA. Lately, the alarm regularly goes off in the middle of the night. It takes quite a bit of time to respond to it and it seems to be a false alarm every time. You decide to set up a hidden camerA. What is such a measure called?
- A. Preventive measure
- B. Detective measure
- C. Repressive measure
正解:B
解説:
Explanation/Reference:
質問 # 52
......
認定試験では、情報セキュリティの概念、リスク管理、インシデント管理、ビジネスの継続管理、コンプライアンス管理など、幅広いトピックをカバーしています。原則と要件を含むISO/IEC 27001標準、およびコントロールを効果的に実装および管理する能力を含む、候補者の理解を調べます。この試験では、情報セキュリティのベストプラクティスと基準に関する候補者の知識も評価します。
ISFS試験問題集パスできる2024年最新の認証された試験問題:https://www.passtest.jp/EXIN/ISFS-shiken.html
ISFS試験問題リアルな最新問題PDF:https://drive.google.com/open?id=1CQnQ_aptv3QAyUi7FZFd7rAMmbDRaoPX